Executive brief
A vulnerability in F5 BIG-IP DNS allows high-privileged administrative users to bypass security restrictions and execute unauthorized system commands. This could lead to a complete takeover of the device, potentially allowing an attacker to intercept or manipulate network traffic and disrupt critical naming services. The risk is particularly high for deployments in 'Appliance mode,' where it allows attackers to cross protected security boundaries.
Technical details
A command injection vulnerability (CWE-77) exists in undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) commands when BIG-IP DNS is provisioned. The flaw allows an authenticated attacker with Resource Administrator or Administrator roles to execute arbitrary system commands with higher privileges than intended. In Appliance mode deployments, this specifically enables a security boundary crossing. The attack vector is network-based, though it requires high-level administrative credentials. F5 has released updates for affected versions including 17.x and 16.x branches to mitigate this issue.
Affected products
- F5 BIG-IP DNS 21.0.0, 17.5.0 to 17.5.1, 17.1.0 to 17.1.3, 16.1.0 to 16.1.6
Timeline
- 2026-05-13: advisory: Initial advisory published by F5 Networks
- 2026-05-13: disclosed